BitgetAPI TradingQuant TradingFee Rebate

Bitget API Setup 2026: Keys, Permissions, Rate Limits, Demo

NOVA888 gives new Bitget users a 40% futures rebate, up to 50% (invite-only). UTA API keys, permissions, IP, rate limits, demo trading, API-ratio rebate rule.

In 2026 Bitget's API centres on the V3 interface of the Unified Trading Account (UTA), with the classic account in maintenance mode. This guide follows Bitget's official API documentation and Help Center (verified 2026-09-28) in the order you would actually integrate: choose the account mode, create an API key with its three credentials, set permissions and IPs, understand signing and rate limits, run on demo trading, and finally the part most people miss: Bitget states in writing that high-volume users trading mostly by API can lose eligibility for platform rebates. Bind Bitget to Quant Nova with referral code NOVA888 and new users get a 40% futures rebate at Lv.1, twice the common 20% referral code, a difference that adds up every month for a program that trades often.

Choose the account mode first: unified or classic

Bitget now has two sets of API documentation. The classic account docs open by recommending the Unified Trading Account and state that the classic account is in maintenance mode, receiving only essential updates (Classic Introduction). The difference:

Write new strategies against UTA; existing V2 code on a classic account keeps working, but the classic account only receives essential updates, and some features, such as the automatic cancel-on-disconnect below, are UTA only. How you integrate does not affect your rebate: binding only needs your UID, never an API key.

A Bitget API key comes with three credentials

Log in on the website and create it under API Key Management. According to the official Quick Start (Quick Start), you end up with three items:

NameWhat it isWatch out for
APIKeyIdentifies your API trading, randomly generatedSent in every request header
SecretKeySystem-generated private key used to signNever share it
PassphraseAPI password you set yourselfCannot be changed; if lost, delete and recreate the key

Bitget's risk warning is blunt: leaking any one of the three may cause loss of assets, and a leaked key should be deleted as soon as possible. Each UID can create up to 50 API keys, each set to read-only or read-write.

Subaccount keys: virtual and standard subaccounts can create and manage their own API keys, provided the main account enables the API Key Management permission for that subaccount, which is off by default; the main account can view, edit or delete subaccount keys at any time. One strategy per subaccount means a problem stays contained.

Permissions and IP binding

The official quick start lists two UTA permission groups, trade and management, each with read-only and read-write; withdrawal permission is specified separately on the withdrawal endpoint:

PermissionWhat it allowsFor a strategy
UTA trade (read-only)View trade informationMonitoring and bookkeeping
UTA trade (read-write)Place and cancel ordersNeeded to trade
UTA management (read-only)View account information and fee ratesNeeded for balances and fees
UTA management (read-write)Account settings such as leverage and holding modeOnly if the strategy adjusts leverage
UTA withdrawalCall the withdrawal endpoint (on-chain and internal transfers)Leave off

The withdrawal permission is the one marked "Permission: UTA withdrawal" on the official /api/v3/account/withdrawal endpoint (Deposit/Withdrawal docs). A trading strategy never needs to withdraw; enable it and a leaked key goes from "unwanted orders" to "assets gone".

IP binding: the Quick Start says twice, in its security tip and risk warning, that binding an IP address when creating an API key is strongly recommended. Per the subaccount key endpoint, one key can bind up to 30 IPs, IPv4 only. As for whether keys without an IP expire, as of 2026-09-28 we found no statement in Bitget's official API docs or Help Center, so go by what the creation page shows; either way, if your server has a fixed outbound IP, bind it.

Signing, timestamps and an example

Every REST request carries four headers: ACCESS-KEY, ACCESS-SIGN, ACCESS-TIMESTAMP and ACCESS-PASSPHRASE. The signature is HMAC-SHA256 with the SecretKey over timestamp + uppercase method + request path + (? and query string, if any) + body, then Base64-encoded; RSA signing is also supported. WebSocket login timestamps expire after 30 seconds, and Bitget recommends syncing your host clock with the server.

This snippet uses the read-only management permission to fetch your futures fee rate, which also proves your signing works. Keys come from environment variables:

import base64, hmac, os, time, requests

KEY = os.environ["BITGET_KEY"]
SECRET = os.environ["BITGET_SECRET"]
PASSPHRASE = os.environ["BITGET_PASSPHRASE"]

path = "/api/v3/account/fee-rate"
query = "category=USDT-FUTURES&symbol=BTCUSDT"   # keys sorted A-Z
ts = str(int(time.time() * 1000))
prehash = ts + "GET" + path + "?" + query
sign = base64.b64encode(
    hmac.new(SECRET.encode(), prehash.encode(), "sha256").digest()
).decode()

r = requests.get("https://api.bitget.com" + path + "?" + query, headers={
    "ACCESS-KEY": KEY, "ACCESS-SIGN": sign, "ACCESS-TIMESTAMP": ts,
    "ACCESS-PASSPHRASE": PASSPHRASE, "Content-Type": "application/json",
})
print(r.json(), r.headers.get("x-mbx-used-remain-limit"))

The response header x-mbx-used-remain-limit shows the remaining allowance for that endpoint, so your code can slow down. For demo trading, see the demo section below.

Rate limits: REST and WebSocket share one allowance

The general rules in the Quick Start: requests that are too frequent return 429 Too Many Requests; each endpoint's limit is listed on its own page and counted separately; REST and WebSocket share the same rate limit quota; and the common domain has an overall cap of 6,000 requests per IP per minute. Common trading endpoints (UTA, Order Management docs, verified 2026-09-28):

EndpointPurposeLimitNotes
/api/v3/trade/place-orderPlace order10/s per UIDStock tokens (rToken) have a separate 5/s
/api/v3/trade/place-batchBatch orders5/s per UIDUp to 20 orders per batch
/api/v3/trade/modify-orderAmend order10/s per UIDNo repeat until the result returns
/api/v3/trade/cancel-orderCancel order10/s per UID
/api/v3/trade/cancel-batchBatch cancel5/s per UIDUp to 20 per batch; partial success allowed
/api/v3/trade/cancel-symbol-orderCancel all by symbol5/s per UID
/api/v3/trade/unfilled-ordersOpen orders20/s per UIDUp to 400 open orders each for futures and spot
/api/v3/account/fee-rateFee rate3/s per UID
/api/v3/account/withdrawalWithdraw1/s per UIDNeeds withdrawal permission

WebSocket rules (the same in the UTA and classic docs):

Bitget's best-practice guide recommends subscribing to the order channel over WebSocket before placing orders and setting your own clientOid; a successful order response only means the exchange received the request and assigned an ID, and whether it reached matching shows up in the order channel.

Extra options for large accounts: countdown cancel-all (countdown-cancel-all, which cancels all orders if no heartbeat arrives within a 5 to 60 second window) is UTA only and must be requested through Bitget's business team; the VIP line and the low-latency Lo-La line are also for VIP and institutional users on application. From 2026-09-03, market maker and PRO users on UTA moved to a new institutional rate limit framework: up to 600 requests per second per account and up to 120,000 per second across a master account and its subaccounts, with classic accounts unchanged (official announcement).

Demo trading: run it on a demo API key first

Bitget's demo trading uses virtual funds against real market prices. The Help Center gives 50,000 USDT as an example and lists USDT-M perpetuals such as BTCUSDT and ETHUSDT, coin-margined BTCUSD and ETHUSD, and USDC-M BTCUSDC and ETHUSDC; virtual funds cannot be withdrawn or moved to your live account, and every user has access by default (What Is Demo Trading on Bitget Futures). To use it through the API (official Quick Start):

  1. Log in and switch to Demo mode.
  2. Go to Personal Center, then API Key Management, and create a Demo API key.
  3. Send REST requests to api.bitget.com as usual, but with the demo key and the header paptrading: 1.
  4. Connect WebSocket to wss://wspap.bitget.com/v3/ws/public and wss://wspap.bitget.com/v3/ws/private.

Unlike Bybit's separate demo domain, Bitget demo REST uses the same domain as live trading, and only the paptrading header tells them apart, so make paptrading an explicit setting in your code to avoid test runs hitting your live account. The Help Center also notes demo prices mirror the real market but may lag slightly due to network latency.

Fees and the rebate rules for API trading

Fees: Bitget's fee schedule is set by VIP level, with VIP0 at 0.1% / 0.1% on spot and 0.02% maker / 0.06% taker on futures, and no separate API rate; check your actual rate with /api/v3/account/fee-rate above. Thresholds and rates by level are in Bitget VIP levels.

Rebates: Bitget's affiliate program defines the rebate as net fees × rebate ratio, where net fees are what you actually paid after deductions; it does not mention API orders separately, so for ordinary users whether API-generated fees count is determined by the settlement records. But Bitget has three API-related exceptions in writing:

Reaching PRO through API volume brings lower listed fees and higher rate limits, but the platform rebate stops. If your account trades close to 100 million USDT a month mostly by API, work out whether PRO fees or VIP fees plus rebate leave you paying less.

Quant users below those thresholds follow the normal rules: Quant Nova's Bitget futures rebate is 40% at Lv.1 for new users, 45% at SVIP (reachable by volume) and up to 50% at the invite-only level; spot is 40% / 45% / 45%. In money terms: 3 million USDT of monthly futures volume, all taker, is about 1,800 USDT in fees, which reaches Lv.4 (1,000 USDT of fees in 30 days) at 43%, about 774 USDT back each month; a common 20% code returns 360 USDT. See the Bitget fee rebate guide, the Bitget rebind guide for existing accounts, and fee rebates for quant traders.

If you are already a VIP on another exchange or trade large volume, contact Quant Nova support: we work directly with the exchange's official team to help you obtain benefits such as a VIP level trial, subject to the exchange's approval.

Need help? Contact support

For any binding or rebate question, or to learn about our exclusive OKX rewards and promotions, reach our support through the channels below.

If you trade at high volume, hold exchange VIP status, or run quantitative strategies, you can also apply here for an upgrade to Supernova — our highest tier, with the highest rebate.

Security: leaked keys, third-party tools and managed-account scams

Refuse anyone who asks for your API key while promising to trade for you with steady profits, and never hand over a key with withdrawal permission. Taiwan's Financial Supervisory Commission warned in a 22 September 2025 press release that scammers use pitches such as "guaranteed, no-loss profits" and "high returns, low risk" to lure people into buying virtual assets, then claim unfreezing fees, deposits or taxes must be paid before any returns can be withdrawn (FSC press release).

On 2026-09-24 Bitget announced unauthorized transfers from some hot wallets and said user balances were not affected; the timeline and reserve ratios are in Bitget proof of reserves. For users in Taiwan: Bitget is not on the FSC list of virtual asset service providers that have completed AML registration (list updated 2026-09-03); see Taiwan VASP registration explained.

FAQ

What if I forget my Bitget API passphrase?

It cannot be recovered or changed. Delete that API key, create a new one, and replace all three credentials in your code.

How many API keys can one Bitget account have?

The Quick Start says up to 50 per UID; subaccounts can create their own once the main account grants the permission.

How many orders per second can I send through the Bitget API?

On UTA, single orders are 10 per second per UID and batch orders 5 per second with up to 20 orders each; REST and WebSocket share the allowance, and excess requests return 429.

Can I use the API on Bitget demo trading?

Yes. Create a demo API key in demo mode, add the paptrading: 1 header to REST requests, and connect WebSocket to wspap.bitget.com.

Do API trades still earn a Bitget rebate?

For ordinary users the settlement records decide. Bitget states two cases are not eligible for the platform rebate: VIPs with 30-day spot volume of 50 million or futures volume of 100 million USDT or more and an API ratio of 20% or more, and PRO and market maker users.

Do I have to give Quant Nova an API key to bind my rebate?

No. Binding only needs your UID, never an API key, password or withdrawal permission.

Further reading

Permissions, rate limits and demo trading rules are from Bitget's official API documentation and Help Center, verified 2026-09-28; Bitget may change its interfaces and limits, and the official documentation is authoritative. The code is an example only; test before trading live. Rebate rates are set by the exchanges and the platform and may change. For information only, not investment advice.

Data verified: 2026-09-28

BitgetBitget — up to 50% fee rebate